CVE-2018-12121
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection), and carefully timed completion of the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.2%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized headers (almost 80 KB per connection), and carefully timed completion of the headers, it is possible to cause the HTTP server to abort from heap allocation failure. Attack potential is mitigated by the use of a load balancer or other proxy layer.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 10.21% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-400
- Affected
- nodejs/node.js · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · redhat/enterprise linux workstation
- Source
- cve-request@iojs.org
References
- http://www.securityfocus.com/bid/106043Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:1821Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2258Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3497Third Party Advisory
- https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/Patch, Vendor Advisory
- https://security.gentoo.org/glsa/202003-48Third Party Advisory
- http://www.securityfocus.com/bid/106043Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2019:1821Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:2258Third Party Advisory
- https://access.redhat.com/errata/RHSA-2019:3497Third Party Advisory
- https://nodejs.org/en/blog/vulnerability/november-2018-security-releases/Patch, Vendor Advisory
- https://security.gentoo.org/glsa/202003-48Third Party Advisory
- https://security.netapp.com/advisory/ntap-20241227-0008/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.